Conversation
…eding a missing one The extension binary carried its file capabilities with the effective bit (setcap ...+eip). The kernel then refuses to exec it as soon as one of them is not granted to the container, so a cluster forbidding a single capability (e.g. NET_ADMIN by policy) got a crash-looping extension. - setcap ...+ip: the binary starts with what the container grants - raise the permitted capabilities to effective at startup, on all threads (extension-kit extruntime.RaiseCapabilities), and log the missing ones - the actions check the capabilities they need when prepared and fail with a message naming the missing ones; the others keep working - e2e: reinstalled without NET_ADMIN, the extension becomes ready, network attacks fail fast naming NET_ADMIN, stress attacks still work Uses extension-kit from steadybit/extension-kit#181 (pseudo-version) until it is released.
|
Claude finished @achoimet's task in 2m 32s —— View job Claude's review
No unresolved review threads from a prior run existed on this PR, so there was nothing to reconcile. Summary: I reviewed A few things I specifically verified because they looked like they could be off, but checked out fine:
I was unable to run |
…d extension-kit commit
…ability only one family needs The e2e run showed that a stress sidecar fails without NET_ADMIN (ioctl SIOCSIFFLAGS: the sidecar brings up the loopback interface of its network namespace), so NET_ADMIN belongs to the capabilities of every sidecar. The degraded-mode e2e case now removes a capability used by a single family.
…ime travel needs the network only to block NTP - shutdown (reboot syscall), time travel (clock change) and CPU speed (cpufreq writes) run in the extension's process, where root helpers cannot help: they now check the effective set (extruntime.MissingHeldCapabilities), which also catches capabilities RaiseCapabilities could not raise - time travel requires the network capabilities only with disableNtp, the clock change needs SYS_TIME alone
Prepare now checks the capabilities of the process, which a test process does not have on Linux; the tests of other behaviour must not depend on the machine they run on. The capability tests stub their own scenarios.
|



Why
The extension binary carries its file capabilities with the effective bit (
setcap …+eip). The kernel then refuses toexecit as soon as one of them is not granted to the container (operation not permitted), so a cluster whose policy forbids a single capability — e.g.NET_ADMINby a Kyverno/Gatekeeper rule — gets a crash-looping extension instead of one where only the attacks needing that capability are unavailable. The chart even warns about it forSYS_RESOURCE.What
setcap …+ip(no effective bit): the binary starts with whatever the container grants.extruntime.RaiseCapabilities, from feat(extruntime): raise capabilities at startup and report missing ones extension-kit#181), and the missing ones are logged.The check uses the bounding set: it is what the container's securityContext grants, and what the root helpers the extension spawns (runc, crun, nsenter, tc, …) inherit through
RootCommandContext.Tests
Prepare.SYS_TIME→ it becomes ready (on main,helm --waittimes out on the crash loop), a time travel fails at prepare namingSYS_TIME, a CPU stress still runs, sidecars are cleaned up; then the default config is restored.The Linux behaviour of
+eipvs+ipwith a missing capability is shown in steadybit/extension-kit#181.Depends on
steadybit/extension-kit#181 —
go.modpoints to its commit (pseudo-version) until extension-kit is released; to be bumped before merging.steadybit/action-kit#512 — action-kit checked
CAP_SYS_PTRACEat package initialization, beforeRaiseCapabilitiesruns, so with+ipevery attack took the slow namespace lookup and logged a false warning (7 times in this PR's E2E logs vs once on main).action_kit_commonspoints to that PR's commit; the pseudo-version readsv1.12.1-0…because the v1.13.0 release commit is not on action-kit's main, but main contains everything in v1.13.0 (the release commit only adds changelog lines). To be bumped to a release before merging.